Back to Blog
CVE-2026-50522: Microsoft SharePoint — Swiss Federal Accounts Compromised (July 2026)
vulnerabilities

CVE-2026-50522: Microsoft SharePoint — Swiss Federal Accounts Compromised (July 2026)

breachwire TeamAug 5, 20262 min read

CVE-2026-50522 — Microsoft SharePoint

CVE-2026-50522 is a high-severity vulnerability in Microsoft SharePoint, actively exploited in July 2026 to compromise user and technical accounts at Switzerland’s Federal Office for Information Technology and Communications (FOITT). The flaw enabled attackers to gain unauthorized access to approximately 200 accounts; no evidence of further data exfiltration has been reported as of this writing.

Attack Vector

Attackers targeted unpatched Microsoft SharePoint servers exposed to the internet, exploiting CVE-2026-50522 to bypass authentication and escalate privileges. The breach was detected on July 28, 2026, after anomalous account activity was observed. The attackers leveraged the vulnerability to compromise both user and technical accounts, indicating lateral movement capabilities. FOITT responded by blocking external internet access to SharePoint, resetting credentials, and reinstalling affected servers.

Who Is at Risk

All organizations running unpatched Microsoft SharePoint servers are at risk, especially those with internet-exposed deployments. The incident specifically impacted the Swiss Federal Office for Information Technology and Communications (FOITT), but the vulnerability is global in scope and could affect any SharePoint environment not yet remediated.

Patch & Mitigate

  • Patch: Apply the latest Microsoft security update addressing CVE-2026-50522 immediately. Refer to Microsoft’s July 2026 security advisory for exact patch details.
  • Workaround: Temporarily restrict external internet access to SharePoint servers if patching is delayed.
  • Detect: Review authentication logs for unusual login attempts, privilege escalations, and access from unfamiliar IP addresses between July 20–31, 2026.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers exploited SharePoint’s external exposure to gain a foothold.
  • TA0005 — Defense Evasion: Use of privilege escalation and account compromise to evade detection.
  • TA0006 — Credential Access: Compromise of user and technical accounts to facilitate further access.

Source: https://securityaffairs.com/196625/hacking/sharepoint-flaws-used-to-hack-switzerlands-federal-it-agency.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: